PT-2024-37643 · WordPress · The News Element Elementor Blog Magazine Wordpress Plugin
Project Black
·
Published
2024-08-16
·
Updated
2025-05-27
·
CVE-2024-6459
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The News Element Elementor Blog Magazine WordPress plugin versions prior to 1.0.6
Description
The issue allows an unauthenticated attacker to include and execute PHP files on the server via the
template parameter, enabling the execution of any PHP code in those files.Recommendations
For versions prior to 1.0.6, update to version 1.0.6 or later to resolve the issue.
As a temporary workaround, consider restricting access to the
template parameter to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
The News Element Elementor Blog Magazine Wordpress Plugin